ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
好的,我现在要帮用户总结这篇文章的内容。用户的要求是用中文,控制在100字以内,不需要特定的开头,直接写文章描述即可。 首先,我需要通读整篇文章,抓住关键信息。文章主要讲的是ShowDoc的一个安全漏洞,编号是CVE-2025-0520,CVSS评分高达9.4。这个漏洞允许攻击者上传任意PHP文件,从而实现远程代码执行。漏洞影响的是ShowDoc 2.8.7之前的版本,已经在2020年修复。 接下来,文章提到这个漏洞最近被积极利用,攻击者在honeypot上植入了web shell。数据显示有超过2000个ShowDoc实例在线,大部分在中国。这说明N日漏洞被广泛利用的情况越来越严重。 现在我要把这些信息浓缩到100字以内。重点包括:ShowDoc的高危漏洞、CVSS评分、攻击方式、受影响版本、修复时间、近期被利用的情况以及实例数量和分布。 可能的结构是:先点出漏洞名称和评分,然后说明攻击方式和影响版本,接着提到修复情况和近期的利用情况,最后补充实例数量和分布。 检查一下字数是否符合要求,并确保语言简洁明了。 </think> ShowDoc文档管理服务发现高危漏洞(CVE-2025-0520),CVSS评分9.4。该漏洞源于文件扩展名验证不当,允许攻击者上传任意PHP文件并远程执行代码。此漏洞影响ShowDoc 2.8.7以下版本,在线实例超2000个,多分布于中国。建议用户升级至最新版本以防范威胁。 2026-4-14 05:50:0 Author: thehackernews.com(查看原文) 阅读量:17 收藏

Vulnerability / Network Security

A critical security vulnerability impacting ShowDoc, a document management and collaboration service popular in China, has come under active exploitation in the wild.

The vulnerability in question is CVE-2025-0520 (aka CNVD-2020-26585), which carries a CVSS score of 9.4 out of 10.0.

It relates to a case of unrestricted file upload that stems from improper validation of file extension, allowing an attacker to upload arbitrary PHP files and achieve remote code execution.

"[In] ShowDoc version before 2.8.7, an unrestricted and unauthenticated file upload issue is found and [an] attacker is able to upload a web shell and execute arbitrary code on server," according to an advisory released by Vulhub. 

The vulnerability was addressed in ShowDoc version 2.8.7, which was shipped in October 2020. The current version of the software is 3.8.1.

According to new details shared by Caitlin Condon, vice president of security research at VulnCheck, CVE-2025-0520 has come under active exploitation for the first time.

The observed exploit involves leveraging the flaw to drop a web shell on a U.S.-based honeypot running a vulnerable version of ShowDoc. Data shared by the company shows that there are more than 2,000 instances of ShowDoc online, most of which are located in China.

The development is the latest example of how threat actors are increasingly exploiting N-day security vulnerabilities, regardless of their install base. Users who are running ShowDoc are advised to update to the latest version for optimal protection.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/04/showdoc-rce-flaw-cve-2025-0520-actively.html
如有侵权请联系:admin#unsafe.sh